Deployment modes: Detect, Detect & Remediate, and Prevent (Inline)

Modified on Wed, Sep 23 at 10:13 AM

Every Check Point policy runs in a protection mode. The mode decides how visible Check Point is and how far it can act: from silently watching, to clawing bad mail back after delivery, to stopping it before it ever reaches the inbox. Choosing the right mode is central to building any policy.

The three modes

Detect — monitor only. Check Point scans and logs, but takes no action and is invisible to users. Nothing is moved or blocked. Ideal for a pilot, or for baselining what is in the environment before you enforce anything.

Detect & Remediate — post-delivery. Microsoft delivers the mail as normal, then Check Point acts through the API after the fact, clawing malicious messages back out of the mailbox. There is a short window where the message sits in the inbox before it is removed.

Prevent (Inline) — pre-delivery. Check Point routes mail through itself before it reaches the inbox, so threats are stopped before the user ever sees them. This is the only mode that can hold a message back, and it is required for Click-Time Protection and outbound DLP or encryption.

Which mode for which feature

  • Threat detection can run in any mode.
  • Click-Time Protection (URL rewriting) requires Prevent (Inline). It has to alter the message before delivery.
  • Outbound DLP and email encryption require Prevent (Inline) for outgoing and internal traffic.

The SPF requirement for inline outbound and internal mail

When you enable Prevent (Inline) for Outgoing or Internal traffic, Check Point's IP addresses are inserted into the delivery chain. To stop your outbound mail failing SPF and being quarantined, add this to your SPF record:

include:spfa.cpmails.com

The same include covers both outgoing and internal traffic, so you only add it once. Mail still sends from Microsoft's IP address; the include simply authorises the Check Point hops so they pass SPF.

Add the SPF include before you enable inline outbound or internal protection, not after. Otherwise legitimate outbound mail can start failing SPF and landing in quarantine.

Next steps

Next: Creating a policy: a worked example with Click-Time Protection

Previous: How Check Point works: engines vs policies

Need Help with Check Point Harmony?

We deploy, configure, and manage Check Point Harmony Email & Collaboration for businesses, making sure your policies, engines, and protection modes are set up correctly so your organisation is fully covered.

Speak to an expert

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article